Skip to main content

2. Framing Options

Welcome to the "Framing Options" page. Here, you'll find a comprehensive table detailing various configuration settings, allowing you to customize which features are displayed to best align with your organization's needs.


Automatic Tailoring


CSFaaS provides three automatic tailoring levels that adjust the interface and functionality to match your organisation’s requirements:

Minimal

Enables basic features, ideal for organisations starting with essential functionality.

  • Framework manager
  • Policy Manager
  • Risk Assessment Management
  • Third party and Systems Management
  • Evidences collection and Form Builder

Medium

Offers a balanced configuration with standard features, ideal for most use cases and allowing for future expansion:

  • Everything in minimal
  • Includes all features from the Minimal level
  • Framework and Policies Manager Versioning
  • Detailed control properties
  • Detailed Risk profiling & SWOT analysis
  • Enhanced Form Builder Integration in Demands and Systems

Optimal

Unlocks the full suite of features for comprehensive coverage and advanced capabilities:

  • Includes all features from the Medium level
  • Detailed Informations in Risk Assessment Demands
  • Inherent Risk Analysis
  • Advanced Third party Options
  • Advanced System Options

Frameworks Menu


Option level 1Option level 2MinimalStandardOptimal
Versioning Capabilities---No.pngYes.pngYes.png
Comments---Yes.pngYes.pngYes.png
Applicability---Yes.pngYes.pngYes.png
Maturity---No.pngYes.pngYes.png
Resource Owners---Yes.pngYes.pngYes.png

Policies Menu


Option level 1Option level 2MinimalStandardOptimal
Versioning Capabilities---No.pngYes.pngYes.png
Pending Framework Actions---Yes.pngYes.pngYes.png
Comments---Yes.pngYes.pngYes.png
Contextual Information---Yes.pngYes.pngYes.png
Maturity---No.pngYes.pngYes.png
Resource Owners---Yes.pngYes.pngYes.png
Control Properties---Yes.pngYes.pngYes.png
Control Progression (or Completion)Yes.pngYes.pngYes.png
Periodicity ReviewNo.pngYes.pngYes.png
Control Maturity LevelNo.pngYes.pngYes.png
WeightingNo.pngYes.pngYes.png
Functional DomainsNo.pngYes.pngYes.png
Business UnitsNo.pngYes.pngYes.png
Control OwnerNo.pngYes.pngYes.png
Information Security PropertyNo.pngYes.pngYes.png
Control FunctionNo.pngYes.pngYes.png
Privacy Control FunctionNo.pngYes.pngYes.png
Security DomainsNo.pngYes.pngYes.png
Control TypeNo.pngYes.pngYes.png
Operational CapabilitiesNo.pngYes.pngYes.png
Link Control to FrameworkNo.pngYes.pngYes.png

Demands Menu


Option level 1Option level 2MinimalStandardOptimal
Comments---Yes.pngYes.pngYes.png
Priority---No.pngYes.pngYes.png
Due Dates---No.pngYes.pngYes.png
Resource Owners---Yes.pngYes.pngYes.png
Demand Information---Yes.pngYes.pngYes.png
Demand TypeNo.pngNo.pngYes.png
Project PhaseNo.pngNo.pngYes.png
Request ImpactNo.pngNo.pngYes.png
RegionNo.pngNo.pngYes.png
CountryNo.pngYes.pngYes.png
Business UnitNo.pngYes.pngYes.png
Functional DomainNo.pngYes.pngYes.png
Data ClassificationNo.pngYes.pngYes.png
Data StateNo.pngYes.pngYes.png
PII / PHINo.pngYes.pngYes.png
Contextual Information---Yes.pngYes.pngYes.png
BGO (Business Goals Objectives)---No.pngNo.pngYes.png
BDS (Business Drivers for Security)---No.pngNo.pngYes.png
Applicable Policies---No.pngNo.pngYes.png
Related Risks---No.pngNo.pngYes.png
Involved Third Parties---No.pngNo.pngYes.png
Involved Systems---No.pngNo.pngYes.png

Risks Menu


Option level 1Option level 2MinimalStandardOptimal
Comments---Yes.pngYes.pngYes.png
Risk Profiling---No.pngYes.pngYes.png
Security DomainNo.pngNo.pngYes.png
Business AttributeNo.pngNo.pngYes.png
Risk CategoryNo.pngNo.pngYes.png
Risk OriginNo.pngNo.pngYes.png
STRIDE Threat ActionNo.pngNo.pngYes.png
Threat VectorNo.pngNo.pngYes.png
Threat ActionNo.pngNo.pngYes.png
Threat ActorNo.pngNo.pngYes.png
Threat Actor MotivationNo.pngNo.pngYes.png
Victim QuantificationNo.pngNo.pngYes.png
Other InformationNo.pngYes.pngYes.png
SWOT Analysis (Inherent)---No.pngNo.pngYes.png
Inherent Risk StatementNo.pngNo.pngYes.png
Inherent StrengthNo.pngNo.pngYes.png
Inherent WeaknessNo.pngNo.pngYes.png
Inherent OpportunityNo.pngNo.pngYes.png
LikelihoodNo.pngNo.pngYes.png
ImpactNo.pngNo.pngYes.png
Risk LevelNo.pngNo.pngYes.png
Impact TypeNo.pngNo.pngYes.png
SWOT Analysis (Current)---Yes.pngYes.pngYes.png
Current Risk StatementYes.pngYes.pngYes.png
Current StrengthNo.pngYes.pngYes.png
Current WeaknessNo.pngYes.pngYes.png
Current OpportunityNo.pngYes.pngYes.png
LikelihoodYes.pngYes.pngYes.png
ImpactYes.pngYes.pngYes.png
Risk LevelYes.pngYes.pngYes.png
Impact TypeNo.pngYes.pngYes.png
Recommended ControlsYes.pngYes.pngYes.png
SWOT Analysis (Target)---Yes.pngYes.pngYes.png
Target Risk StatementYes.pngYes.pngYes.png
Target StrengthNo.pngYes.pngYes.png
Target WeaknessNo.pngYes.pngYes.png
Target OpportunityNo.pngYes.pngYes.png
LikelihoodYes.pngYes.pngYes.png
ImpactYes.pngYes.pngYes.png
Risk LevelYes.pngYes.pngYes.png
Impact Type---No.pngYes.pngYes.png
Risk Response---Yes.pngYes.pngYes.png
OwnerYes.pngYes.pngYes.png
JustificationYes.pngYes.pngYes.png
PeriodicityNo.pngYes.pngYes.png
Remediation Plan---Yes.pngYes.pngYes.png
ContactsYes.pngYes.pngYes.png
Due DateYes.pngYes.pngYes.png
DescriptionYes.pngYes.pngYes.png
Implementation ChallengesNo.pngNo.pngYes.png

Third Parties Menu


Option level 1Option level 2MinimalStandardOptimal
Resource Owners---Yes.pngYes.pngYes.png
Comments---Yes.pngYes.pngYes.png
Information---Yes.pngYes.pngYes.png
Third Party Parent CompanyNo.pngNo.pngYes.png
Third Party Contact NameNo.pngYes.pngYes.png
Third Party Business UnitNo.pngNo.pngYes.png
Third Party RegionNo.pngNo.pngYes.png
Third Party CountryNo.pngNo.pngYes.png
Third Party TypeNo.pngNo.pngYes.png
Third Party IT Provider TypeNo.pngNo.pngYes.png
Third Party Tier LevelNo.pngNo.pngYes.png
Internal Contact---No.pngYes.pngYes.png
Data Classification---No.pngNo.pngYes.png
PII / PHINo.pngNo.pngYes.png
Related Systems---No.pngNo.pngYes.png
Risk Assessments---No.pngNo.pngYes.png
Complementary Information---No.pngNo.pngYes.png

Systems Menu


Option level 1Option level 2MinimalStandardOptimal
Resource Owners---Yes.pngYes.pngYes.png
Comments---Yes.pngYes.pngYes.png
Contacts---No.pngYes.pngYes.png
Business OwnerNo.pngYes.pngYes.png
System OwnerNo.pngYes.pngYes.png
Technical OwnerNo.pngYes.pngYes.png
Information OwnerNo.pngYes.pngYes.png
Other ContactNo.pngYes.pngYes.png
System Information---No.pngNo.pngYes.png
RegionNo.pngNo.pngYes.png
CountryNo.pngNo.pngYes.png
Business UnitNo.pngNo.pngYes.png
Functional DomainNo.pngNo.pngYes.png
CriticalityNo.pngNo.pngYes.png
Internet FacingNo.pngNo.pngYes.png
Environment StageNo.pngNo.pngYes.png
Operational StatusNo.pngNo.pngYes.png
System Details---Yes.pngYes.pngYes.png
Architectural DomainNo.pngNo.pngYes.png
System DomainNo.pngNo.pngYes.png
System AccessibilityNo.pngNo.pngYes.png
System ManagementNo.pngNo.pngYes.png
System HostingNo.pngNo.pngYes.png
Cloud TypeNo.pngNo.pngYes.png
Cloud Stack ComponentsNo.pngNo.pngYes.png
Data Information---No.pngNo.pngYes.png
Data ClassificationNo.pngNo.pngYes.png
PII / PHINo.pngNo.pngYes.png
Recovery---No.pngNo.pngYes.png
Recovery Time Objective (RTO)No.pngNo.pngYes.png
Recovery Point Objective (RPO)No.pngNo.pngYes.png
Related Systems---No.pngNo.pngYes.png
Risk Assessments---No.pngNo.pngYes.png
Complementary Information---Yes.pngYes.pngYes.png

Evidences Menu


Option level 1Option level 2MinimalStandardOptimal
Display in Frameworks---Yes.pngYes.pngYes.png
Display in Policies---Yes.pngYes.pngYes.png
Display in Demands---Yes.pngYes.pngYes.png
Display in Registry---Yes.pngYes.pngYes.png
Display in Remediation Plans---Yes.pngYes.pngYes.png
Display in Third Parties---Yes.pngYes.pngYes.png
Display in Systems---Yes.pngYes.pngYes.png

Form Builders Menu


Option level 1Option level 2MinimalStandardOptimal
Display in Demands---No.pngYes.pngYes.png
Display in Third Parties---Yes.pngYes.pngYes.png
Display in System---No.pngYes.pngYes.png